CVE-2019-20907
13.07.2020, 13:15
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
| Vendor | Product | Version |
|---|---|---|
| python | python | 3.5.0 ≤ 𝑥 < 3.5.10 |
| python | python | 3.6.0 ≤ 𝑥 < 3.6.12 |
| python | python | 3.7.0 ≤ 𝑥 < 3.7.9 |
| python | python | 3.8.0 ≤ 𝑥 < 3.8.5 |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 20.04 |
| netapp | active_iq_unified_manager | 9.5 ≤ |
| netapp | cloud_volumes_ontap_mediator | - |
| oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python2.7 |
| ||||||||||||||||||||||||||
| python3.4 |
| ||||||||||||||||||||||||||
| python3.5 |
| ||||||||||||||||||||||||||
| python3.6 |
| ||||||||||||||||||||||||||
| python3.7 |
| ||||||||||||||||||||||||||
| python3.8 |
|
Common Weakness Enumeration
References